Bill Dougherty — INCLUDES NO DIRT, practical threat modeling for healthcare and beyond episode artwork

EPISODE · Nov 21, 2019 · 32 MIN

Bill Dougherty — INCLUDES NO DIRT, practical threat modeling for healthcare and beyond

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What happens when a threat model has to account for patient privacy and clinical harm as well as attackers? Bill Dougherty joins Chris and Robert to explain INCLUDES NO DIRT, the model he developed with Patrick Curry at Omada Health. They discuss why conventional security categories did not fully capture digital healthcare's competing security, privacy, and compliance needs, and how combining ideas from existing frameworks produced a memorable checklist. Bill walks through the practical workflow, from understanding a system and drawing data flows to asking targeted questions and prioritizing deeper review. The conversation also covers training product teams to use the model themselves, avoiding checkbox risk assessments, and adapting the published questionnaires to the risks an organization actually needs to understand.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Bill Dougherty:→ LinkedIn→ INCLUDES NO DIRT at Omada HealthMentioned in this episode:→ LINDDUN privacy threat modeling→ Microsoft threat modelingFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction02:17 Bill's path into security leadership04:21 Security responsibilities at Omada Health06:38 Why digital healthcare needed another threat model10:20 The INCLUDES NO DIRT acronym11:09 Security, privacy, and clinical threat categories12:33 What makes healthcare different14:07 Turning the categories into a practical process18:21 Diagrams and understanding the system21:08 Applying the checklist to data flows23:35 Helping product teams become self-sufficient25:11 Requirements and compliance considerations27:00 Getting started with the questionnaires30:07 Closing thoughts

Episode metadata supplied by the publisher feed · Published Nov 21, 2019

Embed this episode

What happens when a threat model has to account for patient privacy and clinical harm as well as attackers? Bill Dougherty joins Chris and Robert to explain INCLUDES NO DIRT, the model he developed with Patrick Curry at Omada Health. They discuss why conventional security categories did not fully capture digital healthcare's competing security, privacy, and compliance needs, and how combining ideas from existing frameworks produced a memorable checklist. Bill walks through the practical workf...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Bill Dougherty — INCLUDES NO DIRT, practical threat modeling for healthcare and beyond

0:00 32:08

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 32 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 21, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!